📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Consumer Electronics / Technology CRITICAL 1h Global ransomware Enterprise / All Sectors CRITICAL 1h Global data_breach Government CRITICAL 3h Global malware Multiple sectors / General public HIGH 3h Global vulnerability Technology and Software Development CRITICAL 4h Global malware,vulnerability,apt Technology, Cloud Services, Consumer Electronics HIGH 4h Global malware Web Hosting and Content Management HIGH 4h Global vulnerability Information Technology and Network Infrastructure CRITICAL 5h Global general All MEDIUM 6h Global general All MEDIUM 6h Global vulnerability Consumer Electronics / Technology CRITICAL 1h Global ransomware Enterprise / All Sectors CRITICAL 1h Global data_breach Government CRITICAL 3h Global malware Multiple sectors / General public HIGH 3h Global vulnerability Technology and Software Development CRITICAL 4h Global malware,vulnerability,apt Technology, Cloud Services, Consumer Electronics HIGH 4h Global malware Web Hosting and Content Management HIGH 4h Global vulnerability Information Technology and Network Infrastructure CRITICAL 5h Global general All MEDIUM 6h Global general All MEDIUM 6h Global vulnerability Consumer Electronics / Technology CRITICAL 1h Global ransomware Enterprise / All Sectors CRITICAL 1h Global data_breach Government CRITICAL 3h Global malware Multiple sectors / General public HIGH 3h Global vulnerability Technology and Software Development CRITICAL 4h Global malware,vulnerability,apt Technology, Cloud Services, Consumer Electronics HIGH 4h Global malware Web Hosting and Content Management HIGH 4h Global vulnerability Information Technology and Network Infrastructure CRITICAL 5h Global general All MEDIUM 6h Global general All MEDIUM 6h
Vulnerabilities

CVE-2026-5211

High ⚡ Exploit Available
A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1
CWE-119 — Weakness Type
Published: Mar 31, 2026  ·  Modified: Apr 7, 2026  ·  Source: NVD
CVSS v3
8.8
🔗 NVD Official
📄 Description (English)

A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This vulnerability affects the function UPnP_AV_Server_Path_Del of the file /cgi-bin/app_mgr.cgi. Executing a manipulation of the argument f_dir can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been published and may be used.

🤖 AI Executive Summary

A critical stack-based buffer overflow vulnerability exists in D-Link NAS devices (DNS and DNR series) affecting the UPnP AV Server functionality through the /cgi-bin/app_mgr.cgi endpoint. The flaw allows remote attackers to execute arbitrary code by manipulating the f_dir parameter, with public exploits already available. This poses an immediate threat to organizations using these devices for network storage and backup operations.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Apr 23, 2026 16:02
🇸🇦 Saudi Arabia Impact Assessment
Saudi organizations in banking, government, healthcare, and energy sectors utilizing D-Link NAS devices for centralized data storage and backup are at significant risk. ARAMCO facilities, SAMA-regulated financial institutions, and government agencies (NCA, MOI) relying on these devices for critical data management face potential data breach, system compromise, and operational disruption. Telecom operators (STC, Mobily) using these devices for network infrastructure storage are also vulnerable. The lack of available patches creates an extended exposure window.
🏢 Affected Saudi Sectors
Banking and Financial Services Government and Public Administration Healthcare and Medical Institutions Energy and Utilities (ARAMCO) Telecommunications (STC, Mobily) Education and Research Enterprise IT Infrastructure
⚖️ Saudi Risk Score (AI)
8.9
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify and inventory all D-Link DNS/DNR series devices in your environment using network scanning tools
2. Isolate affected devices from internet-facing networks immediately; restrict access to trusted internal networks only
3. Disable UPnP functionality if not operationally required via device web interface
4. Implement network segmentation to limit lateral movement from compromised devices

COMPENSATING CONTROLS (until patch available):
5. Deploy Web Application Firewall (WAF) rules to block requests to /cgi-bin/app_mgr.cgi with suspicious f_dir parameters
6. Implement strict input validation rules: block requests containing path traversal sequences (../, ..\ ) in f_dir parameter
7. Monitor for exploitation attempts using IDS/IPS signatures detecting buffer overflow patterns
8. Enable detailed logging on affected devices and forward logs to SIEM for analysis
9. Restrict administrative access to device management interfaces using IP whitelisting
10. Consider replacing affected devices with patched alternatives from D-Link or alternative vendors

DETECTION RULES:
- Monitor HTTP POST requests to /cgi-bin/app_mgr.cgi with f_dir parameter exceeding 256 bytes
- Alert on UPnP_AV_Server_Path_Del function calls with abnormal parameter lengths
- Track failed authentication attempts and unusual process execution on NAS devices
- Monitor for reverse shell indicators and unexpected outbound connections from NAS devices
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد وحصر جميع أجهزة D-Link DNS/DNR في بيئتك باستخدام أدوات المسح الشبكي
2. عزل الأجهزة المتأثرة عن الشبكات المتصلة بالإنترنت فوراً؛ تقييد الوصول إلى الشبكات الداخلية الموثوقة فقط
3. تعطيل وظيفة UPnP إذا لم تكن مطلوبة تشغيلياً عبر واجهة الويب للجهاز
4. تنفيذ تقسيم الشبكة لتحديد الحركة الجانبية من الأجهزة المخترقة

الضوابط البديلة (حتى توفر التصحيح):
5. نشر قواعد جدار حماية تطبيقات الويب (WAF) لحجب الطلبات إلى /cgi-bin/app_mgr.cgi بمعاملات f_dir مريبة
6. تنفيذ قواعد التحقق من صحة الإدخال الصارمة: حجب الطلبات التي تحتوي على تسلسلات اجتياز المسار (../, ..\ ) في معامل f_dir
7. مراقبة محاولات الاستغلال باستخدام توقيعات IDS/IPS التي تكتشف أنماط تجاوز المخزن المؤقت
8. تفعيل السجلات التفصيلية على الأجهزة المتأثرة وإعادة توجيه السجلات إلى SIEM للتحليل
9. تقييد الوصول الإداري إلى واجهات إدارة الجهاز باستخدام القائمة البيضاء للعناوين
10. النظر في استبدال الأجهزة المتأثرة بأجهزة معدلة من D-Link أو بدائل من بائعين آخرين
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.12.6.1 - Management of technical vulnerabilities ECC 2024 A.14.2.1 - Secure development policy ECC 2024 A.12.2.1 - Monitoring and logging of access
🔵 SAMA CSF
ID.RA-1 - Asset management and vulnerability identification PR.IP-12 - Security patch management DE.CM-1 - Detection and analysis of anomalies
🟡 ISO 27001:2022
A.12.6.1 - Management of technical vulnerabilities A.14.2.1 - Secure development policy and procedures A.12.4.1 - Event logging A.13.1.1 - Network security perimeter
🟣 PCI DSS v4.0.1
Requirement 6.2 - Security patches and updates Requirement 11.2 - Vulnerability scanning
📦 Affected Products / CPE 20 entries
dlink:dnr-202l_firmware
dlink:dnr-326_firmware
dlink:dns-1100-4_firmware
dlink:dns-120_firmware
dlink:dns-1200-05_firmware
dlink:dns-1550-04_firmware
dlink:dns-315l_firmware
dlink:dns-320_firmware
dlink:dns-320l_firmware
dlink:dns-320lw_firmware
dlink:dns-321_firmware
dlink:dns-322l_firmware
dlink:dns-323_firmware
dlink:dns-325_firmware
dlink:dns-326_firmware
dlink:dns-327l_firmware
dlink:dns-340l_firmware
dlink:dns-343_firmware
dlink:dns-345_firmware
dlink:dns-726-4_firmware
📊 CVSS Score
8.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score8.8
CWECWE-119
EPSS0.03%
Exploit ✓ Yes
Patch ✗ No
Published 2026-03-31
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
8.9
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
exploit-available CWE-119
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.